CND Cheat Sheet 2026
The 30 highest-yield CND facts, distilled from real exam questions. Print it, save it as a PDF, or study it here β free, no sign-up.
100 questions
240 min time limit
70% to pass
- What is the function of a Security Information and Event Management (SIEM) system? β To monitor, detect, and respond to security incidents by analyzing event data
- Which incident response phase involves removing malware, closing vulnerabilities, and restoring affected systems to normal operation? β Eradication
- Which CND control specifically addresses preventing unauthorized software execution on endpoints through policy-based restrictions? β Software Restriction Policies (SRP) or AppLocker
- When performing forensic disk imaging, which tool creates a bit-for-bit copy and generates an MD5/SHA hash to verify integrity? β dd or dcfldd
- Which network security measure is used to authenticate users based on their physical characteristics? β Biometric authentication
- Which MITRE framework maps adversary tactics, techniques, and procedures (TTPs) and is widely used to inform threat assessments and detection strategies? β MITRE ATT&CK
- Which protocol provides centralized AAA (Authentication, Authorization, and Accounting) services and is commonly used with network devices via TCP port 49? β TACACS+
- Which Windows artifact is most useful for determining which programs were recently executed on a system? β Prefetch files
- Why is multi-factor authentication (MFA) important for protecting endpoint access? β It ensures an attacker with stolen credentials alone cannot log in
- What is the primary function of a Demilitarized Zone (DMZ) in a network? β To provide a secure zone for public-facing services while protecting internal networks
- Why is regular vulnerability scanning important in network security? β To identify and address vulnerabilities before they are exploited
- What is the PRIMARY purpose of obtaining CND certification in Certified Network Defender? β To demonstrate verified competency and adherence to professional standards
- What is the key difference between IDS and IPS deployment in a network? β IPS is placed inline and can block traffic; IDS passively monitors
- What is the significance of timestamps in log analysis during a forensic investigation? β They establish the sequence and timing of events
- Which tool is commonly used for capturing and analyzing raw network packets during forensic investigation? β Wireshark
- Which NIST SP 800-53 control family specifically addresses planning and policy for information security? β Planning (PL)
- Which activity in a risk management program involves continuously tracking identified risks, monitoring residual risk, and identifying new risks over time? β Risk monitoring and review
- What does the concept of containment refer to during an incident response? β To limit the spread of the incident, minimizing further damage
- What does a next-generation firewall (NGFW) provide that a traditional stateful firewall does not? β Deep packet inspection and application awareness
- Which GDPR principle requires that personal data be collected only for specified, explicit, and legitimate purposes? β Purpose limitation
- What is the MOST important leadership quality for a CND certified professional managing a team? β Demonstrating integrity, clear communication, and ability to develop team members
- Which artifact should an incident responder collect FIRST from a live Windows system before pulling the power? β Contents of RAM (memory dump)
- Which type of malware analysis runs a suspicious file in an isolated environment to observe its behavior without risking production systems? β Dynamic analysis (sandboxing)
- Under GDPR, what is the maximum timeframe within which a data breach affecting EU citizens' rights must be reported to the supervisory authority? β 72 hours
- How does a risk assessment help with vulnerability management? β By helping prioritize vulnerabilities based on their risk to the organization
- What is a zero-day vulnerability? β A vulnerability that is exploited immediately upon discovery, without a fix available
- Which risk analysis method uses expert opinion and descriptive ratings such as 'High,' 'Medium,' and 'Low' rather than numerical values? β Qualitative analysis
- What is the purpose of Windows Defender Credential Guard? β Isolate and protect NTLM/Kerberos credential hashes in a virtualized container from theft
- What is the significance of incident response testing? β To test the planβs effectiveness and make necessary improvements
- What is the primary function of a Security Information and Event Management (SIEM) system in incident response? β Aggregating and correlating log data from multiple sources to detect incidents
Turn these facts into recall:
Was this helpful?